Vovy adds your keys as encrypted GitHub Actions secrets, wires them into the workflow, and confirms they stay masked in logs.
My GitHub Action needs my Supabase key, add it as a secret
How it works
- Find what the workflow needs: Vovy reads your workflow file and the failing run to list every variable it expects, like SUPABASE_SERVICE_ROLE_KEY.
- Copy the values: Vovy opens your Supabase project's API keys page in your signed-in browser to get each value.
- Add repository secrets: Vovy goes to Settings, Secrets and variables, Actions, clicks New repository secret, and saves each key. They are encrypted and cannot be read back.
- Reference them in the workflow: Vovy wires each one in with the ${{ secrets.NAME }} syntax under env, so the value never appears in your code.
- Rerun and verify: Vovy reruns the job, checks it passes, and shows that the log displays *** in place of each secret.
What you provide
- Admin access to the repo
- Access to the service dashboards
What you get
- Encrypted Actions secrets
- Workflow wired to use them
- A passing run
- Proof secrets are masked in logs
FAQ
Can I see a secret after I save it?
No. GitHub only lets you update or delete it. Keep the original in your password manager.
Secrets or variables?
Use secrets for keys and passwords. Variables are for non-sensitive settings like a region, and are shown in plain text.
Do pull requests from forks get my secrets?
No. By default GitHub does not pass secrets to workflows triggered by forks, which protects you from strangers.
Related tasks
All tasks